fix: 301 every www.seofixkit.com request incl. static assets via run_worker_first: true - #107
Conversation
…worker_first: true The canonical-host 301 in worker/index.js only fires for requests that reach the Worker; wrangler.jsonc's run_worker_first path list let static asset requests (/assets/*, /favicon.svg, /og-image.svg, /apple-touch-icon.svg, /security.txt) bypass the Worker and be served 200 straight from the asset CDN on the www host. With run_worker_first: true every www request 301s onto the apex, so no second host ever serves bytes or leaks into canonicals/sitemap. - Lock the Worker-level guarantee with static-asset 301 assertions - Add a live spot-check for a www static-asset 301 (catches config drift) - Document the asset coverage in the README Custom domain section
…hecks pages.test.mjs and promise-audit.test.mjs parsed wrangler.jsonc as strict JSON and asserted the run_worker_first path list still named /check. With run_worker_first: true every request runs the Worker first, which is a stronger guarantee (covers static assets on www); update both offline locks to accept the boolean form and fail if the config regresses to missing or false.
There was a problem hiding this comment.
nish3451 has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Free Run ID: 📒 Files selected for processing (7)
📝 WalkthroughWalkthroughThe assets configuration now runs the Worker first for all requests. Redirect tests cover static assets from ChangesCanonical asset redirects
Estimated code review effort: 2 (Simple) | ~10 minutes Note 🎁 Summarized by CodeRabbit FreeYour organization is on the Free plan. CodeRabbit will generate a high-level summary and a walkthrough for each pull request. For a comprehensive line-by-line review, please upgrade your subscription to CodeRabbit Pro by visiting https://app.coderabbit.ai/login. Comment |
There was a problem hiding this comment.
nish3451 has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 1c9a51de3c
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| "binding": "ASSETS", | ||
| "not_found_handling": "404-page", | ||
| "run_worker_first": ["/", "/api/*", "/v1/*", "/admin/*", "/beta", "/beta/*", "/demo", "/methodology", "/packages", "/check", "/r/*", "/.well-known/seofixkit-report-domain.txt", "/llms.txt", "/privacy", "/support", "/terms", "/robots.txt", "/sitemap.xml", "/fixture/*"] | ||
| // Every request must run the Worker first (not just the listed routes) so |
There was a problem hiding this comment.
Preserve strict-JSON compatibility for the audit runner
These newly added comments make the file invalid JSON, but readDodoPublicConfig() in scripts/run-live-audit-batch.mjs:534 still reads it with JSON.parse. When the documented Fix Pack webhook drill runs without both public Dodo IDs duplicated in environment variables, it falls back to this file and now throws a SyntaxError before constructing the drill event. Keep this config strict JSON or update that reader to parse JSONC.
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
nish3451 has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
There was a problem hiding this comment.
nish3451 has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
There was a problem hiding this comment.
nish3451 has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
There was a problem hiding this comment.
nish3451 has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
There was a problem hiding this comment.
Your trial has ended. Reactivate Greptile to resume code reviews.
There was a problem hiding this comment.
Your trial has ended. Reactivate Greptile to resume code reviews.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f6b5a04da6
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| assert.equal( | ||
| runWorkerFirst === true || Array.isArray(runWorkerFirst), | ||
| true, |
There was a problem hiding this comment.
Require boolean worker-first routing in the regression test
Require runWorkerFirst === true here. The previous path-array configuration still satisfies this assertion and the subsequent page checks, yet it lets /favicon.svg and /assets/* bypass the Worker on www, recreating the exact canonical-host regression this commit addresses. The live spot-check unit test uses a mocked redirect and the real live audit is opt-in, so the normal offline CI suite would not catch such a configuration rollback.
Useful? React with 👍 / 👎.
…n — /check free-entry surface live-stale, window must not start (#134) `npm run audit:live-promise` fails on 9 of 16 surfaces against the deployed site (pre-#85/#88/#90/#100/#107 copy: missing no-storage disclosure on /check, missing footer terms/privacy links on /demo /methodology /packages, missing /check cross-links on /support /terms /privacy, 422-vs-400 on non-http scheme, www static asset 200-vs-301). Root cause is the fleet release deploying a stale Worker + assets bundle on 2026-08-13 22:40 (its log says "No updated asset files to upload" while recording index-Dd3Lei8e.js as the marker; live serves the older index-DX7O9nYF.js). Repo source is green (npm run check + offline spot-check lock pass); this is deploy machinery, not copy drift. The experiment log now carries the dated precondition note so the founder does not start the seven-day window against a broken /check, plus the resume condition (re-verify after a release that actually swaps the live Worker). Co-authored-by: minimax-vps-lane1 <minimax-vps@nish.fleet> Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
…21f0364 (#162) Item 38147c59f9 (canonicalize www.seofixkit.com onto the apex host with 301 redirects and apex-only canonicals/sitemap) is already implemented, tested, and live on origin/main. PR #70 (commit c05fae5, 2026-08-09) shipped the 301 + apex-only canonicals/robots/sitemap/llms.txt; PR #107 (commit f5b2349) extended it to static assets via run_worker_first. Re-verified today against origin/main at 21f0364: npm run test:worker-dispatch passes 12/12 (covers www root, deep path with query, /api/health, /sitemap.xml, asset layer /favicon.svg + /assets/*); repo has no www serving URL anywhere outside the redirect logic, its regression locks, the deliberate app-host allowlists, the wrangler routes config, and the live spot-check script. Live spot checks: www root, /packages?utm_source=scout, /sitemap.xml, /favicon.svg, and /llms.txt all 301 to apex with path/query intact; apex sitemap/robots/ canonicals are apex-only. No code change needed; report only. Co-authored-by: fleet-dispatch <fleet-dispatch@local>
…7783adc (#171) Item 38147c59f9 (canonicalize www.seofixkit.com onto the apex host with 301 redirects and apex-only canonicals/sitemap) is already implemented, tested, and live on origin/main. PR #70 (commit c05fae5, 2026-08-09) shipped the 301 + apex-only canonicals/robots/sitemap/llms.txt; #107 added run_worker_first so www static assets 301 too; #89 hardened the live spot-check. Re-verified today against origin/main at 7783adc: test:worker-dispatch 14/14, test:public-pages 15/15, test:promise-audit 71/71; live www root, deep path with query, sitemap.xml, llms.txt, favicon.svg, well-known and SPA-fallback paths all 301 to the apex with path/query intact; apex sitemap/robots/canonicals are apex-only. No code change needed; report only. Co-authored-by: fleet-dispatch <fleet-dispatch@local> Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
What and why
Scout item: canonicalize
www.seofixkit.comonto the apex host with 301 redirects and apex-only canonicals/sitemap.PR #70 already shipped the Worker-level canonicalization (301 for worker-routed paths, apex-only canonicals/robots/sitemap/llms, unit tests, live spot-checks). Live verification confirmed it works for pages. But the config let static assets bypass the Worker:
assets.run_worker_firstwas a path list, so non-listed requests are served straight from the asset CDN without touching the Workerhttps://www.seofixkit.com/favicon.svg,/og-image.svg,/apple-touch-icon.svg,/security.txt, and/assets/*.css|jsall returned 200 on the www host — a second host serving bytes, contradicting the README claim that "everywww.seofixkit.comrequest" 301sFix
wrangler.jsonc:run_worker_first: true(boolean) — every request runs the Worker first, so the existing www→apex 301 now covers asset paths too. The Worker'sASSETS.fetchfallthrough keeps apex behavior byte-identical. Validated withwrangler deploy --dry-run.worker/index.test.mjs: static-asset 301 assertions added to the www redirect testscripts/live-promise-spot-check.mjs: new live check that a www static asset (/favicon.svg) 301s to apex — catches config drift on the deployed siteworker/routes/pages.test.mjs+shared/promise-audit.test.mjs: offline locks updated for the boolean form (they parsed wrangler.jsonc as strict JSON and asserted the path list)Validation
npm run check(the CI gate): exit 0, all suites passnpx wrangler deploy --dry-run: config validSummary by CodeRabbit
New Features
www.seofixkit.comto the canonical apex domain while preserving the asset path.Bug Fixes
Tests